From ec8bfb4f6db093e03cd872db5aef938489143d75 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Mon, 8 Jan 2024 09:31:43 +0000 Subject: [PATCH] Publish Advisories GHSA-2rcq-rfc3-h2m5 GHSA-2w87-fjj9-j39h GHSA-4p4p-22cr-2gqw GHSA-6vcr-w6p9-3j89 GHSA-9rm8-w7j5-j66w GHSA-fc57-gm4x-m594 GHSA-gwr5-jm6x-gfh6 GHSA-hwrv-r72x-jcwr GHSA-mvp3-ghv2-w5rp GHSA-pgpx-675x-4jcv GHSA-v525-j46w-8q9c GHSA-w69p-f797-2jf5 GHSA-xr84-qwr9-vj33 --- .../GHSA-2rcq-rfc3-h2m5.json | 46 +++++++++++++++++++ .../GHSA-2w87-fjj9-j39h.json | 42 +++++++++++++++++ .../GHSA-4p4p-22cr-2gqw.json | 42 +++++++++++++++++ .../GHSA-6vcr-w6p9-3j89.json | 46 +++++++++++++++++++ .../GHSA-9rm8-w7j5-j66w.json | 42 +++++++++++++++++ .../GHSA-fc57-gm4x-m594.json | 46 +++++++++++++++++++ .../GHSA-gwr5-jm6x-gfh6.json | 35 ++++++++++++++ .../GHSA-hwrv-r72x-jcwr.json | 42 +++++++++++++++++ .../GHSA-mvp3-ghv2-w5rp.json | 46 +++++++++++++++++++ .../GHSA-pgpx-675x-4jcv.json | 42 +++++++++++++++++ .../GHSA-v525-j46w-8q9c.json | 46 +++++++++++++++++++ .../GHSA-w69p-f797-2jf5.json | 46 +++++++++++++++++++ .../GHSA-xr84-qwr9-vj33.json | 42 +++++++++++++++++ 13 files changed, 563 insertions(+) create mode 100644 advisories/unreviewed/2024/01/GHSA-2rcq-rfc3-h2m5/GHSA-2rcq-rfc3-h2m5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json create mode 100644 advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json create mode 100644 advisories/unreviewed/2024/01/GHSA-6vcr-w6p9-3j89/GHSA-6vcr-w6p9-3j89.json create mode 100644 advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json create mode 100644 advisories/unreviewed/2024/01/GHSA-fc57-gm4x-m594/GHSA-fc57-gm4x-m594.json create mode 100644 advisories/unreviewed/2024/01/GHSA-gwr5-jm6x-gfh6/GHSA-gwr5-jm6x-gfh6.json create mode 100644 advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json create mode 100644 advisories/unreviewed/2024/01/GHSA-mvp3-ghv2-w5rp/GHSA-mvp3-ghv2-w5rp.json create mode 100644 advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json create mode 100644 advisories/unreviewed/2024/01/GHSA-v525-j46w-8q9c/GHSA-v525-j46w-8q9c.json create mode 100644 advisories/unreviewed/2024/01/GHSA-w69p-f797-2jf5/GHSA-w69p-f797-2jf5.json create mode 100644 advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json diff --git a/advisories/unreviewed/2024/01/GHSA-2rcq-rfc3-h2m5/GHSA-2rcq-rfc3-h2m5.json b/advisories/unreviewed/2024/01/GHSA-2rcq-rfc3-h2m5/GHSA-2rcq-rfc3-h2m5.json new file mode 100644 index 00000000000..f31ecb3ae78 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2rcq-rfc3-h2m5/GHSA-2rcq-rfc3-h2m5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2rcq-rfc3-h2m5", + "modified": "2024-01-08T09:30:34Z", + "published": "2024-01-08T09:30:34Z", + "aliases": [ + "CVE-2024-0302" + ], + "details": "A vulnerability, which was classified as critical, has been found in fhs-opensource iparking 1.5.22.RELEASE. This issue affects some unknown processing of the file /vueLogin. The manipulation leads to deserialization. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249869 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0302" + }, + { + "type": "WEB", + "url": "https://github.com/laoquanshi/heishou/blob/main/Iparking%20rce.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249869" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249869" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-502" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T07:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json b/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json new file mode 100644 index 00000000000..43be1cbc6f3 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-2w87-fjj9-j39h/GHSA-2w87-fjj9-j39h.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2w87-fjj9-j39h", + "modified": "2024-01-08T09:30:34Z", + "published": "2024-01-08T09:30:34Z", + "aliases": [ + "CVE-2023-29048" + ], + "details": "A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29048" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0005.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T09:15:19Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json b/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json new file mode 100644 index 00000000000..3fe9921275f --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-4p4p-22cr-2gqw/GHSA-4p4p-22cr-2gqw.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p4p-22cr-2gqw", + "modified": "2024-01-08T09:30:35Z", + "published": "2024-01-08T09:30:35Z", + "aliases": [ + "CVE-2023-29050" + ], + "details": "The optional \"LDAP contacts provider\" could be abused by privileged users to inject LDAP filter strings that allow to access content outside of the intended hierarchy. Unauthorized users could break confidentiality of information in the directory and potentially cause high load on the directory server, leading to denial of service. Encoding has been added for user-provided fragments that are used when constructing the LDAP query. No publicly available exploits are known.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29050" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0005.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-90" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T09:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-6vcr-w6p9-3j89/GHSA-6vcr-w6p9-3j89.json b/advisories/unreviewed/2024/01/GHSA-6vcr-w6p9-3j89/GHSA-6vcr-w6p9-3j89.json new file mode 100644 index 00000000000..e9633f71ea9 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-6vcr-w6p9-3j89/GHSA-6vcr-w6p9-3j89.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6vcr-w6p9-3j89", + "modified": "2024-01-08T09:30:34Z", + "published": "2024-01-08T09:30:34Z", + "aliases": [ + "CVE-2024-0303" + ], + "details": "A vulnerability, which was classified as critical, was found in Youke365 up to 1.5.3. Affected is an unknown function of the file /app/api/controller/caiji.php of the component Parameter Handler. The manipulation of the argument url leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-249870 is the identifier assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0303" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/fssH60eQkvSl" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249870" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249870" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T08:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json b/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json new file mode 100644 index 00000000000..e72359946a6 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-9rm8-w7j5-j66w/GHSA-9rm8-w7j5-j66w.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rm8-w7j5-j66w", + "modified": "2024-01-08T09:30:35Z", + "published": "2024-01-08T09:30:35Z", + "aliases": [ + "CVE-2023-41710" + ], + "details": "User-defined script code could be stored for a upsell related shop URL. This code was not correctly sanitized when adding it to DOM. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-41710" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T09:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-fc57-gm4x-m594/GHSA-fc57-gm4x-m594.json b/advisories/unreviewed/2024/01/GHSA-fc57-gm4x-m594/GHSA-fc57-gm4x-m594.json new file mode 100644 index 00000000000..41e4017d6c5 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-fc57-gm4x-m594/GHSA-fc57-gm4x-m594.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fc57-gm4x-m594", + "modified": "2024-01-08T09:30:35Z", + "published": "2024-01-08T09:30:35Z", + "aliases": [ + "CVE-2024-0306" + ], + "details": "A vulnerability was found in Kashipara Dynamic Lab Management System up to 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_login_process.php. The manipulation of the argument admin_password leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-249873 was assigned to this vulnerability.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0306" + }, + { + "type": "WEB", + "url": "https://github.com/E1CHO/cve_hub/blob/main/Dynamic%20Lab%20Management%20System%20-%20vuln%201.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249873" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249873" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T09:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-gwr5-jm6x-gfh6/GHSA-gwr5-jm6x-gfh6.json b/advisories/unreviewed/2024/01/GHSA-gwr5-jm6x-gfh6/GHSA-gwr5-jm6x-gfh6.json new file mode 100644 index 00000000000..6a3c495c203 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-gwr5-jm6x-gfh6/GHSA-gwr5-jm6x-gfh6.json @@ -0,0 +1,35 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwr5-jm6x-gfh6", + "modified": "2024-01-08T09:30:34Z", + "published": "2024-01-08T09:30:34Z", + "aliases": [ + "CVE-2024-22216" + ], + "details": "In default installations of Microchip maxView Storage Manager (for Adaptec Smart Storage Controllers) where Redfish server is configured for remote system management, unauthorized access can occur, with data modification and information disclosure. This affects 3.00.23484 through 4.14.00.26064 (except for the patched versions 3.07.23980 and 4.07.00.25339).", + "severity": [ + + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-22216" + }, + { + "type": "WEB", + "url": "https://www.microchip.com/en-us/solutions/embedded-security/how-to-report-potential-product-security-vulnerabilities/maxview-storage-manager-redfish-server-vulnerability" + } + ], + "database_specific": { + "cwe_ids": [ + + ], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T07:15:11Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json b/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json new file mode 100644 index 00000000000..7b522ba808d --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-hwrv-r72x-jcwr/GHSA-hwrv-r72x-jcwr.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwrv-r72x-jcwr", + "modified": "2024-01-08T09:30:35Z", + "published": "2024-01-08T09:30:35Z", + "aliases": [ + "CVE-2023-29051" + ], + "details": "User-defined OXMF templates could be used to access a limited part of the internal OX App Suite Java API. The existing switch to disable the feature by default was not effective in this case. Unauthorized users could discover and modify application state, including objects related to other users and contexts. We now make sure that the switch to disable user-generated templates by default works as intended and will remove the feature in future generations of the product. No publicly available exploits are known.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29051" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T09:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-mvp3-ghv2-w5rp/GHSA-mvp3-ghv2-w5rp.json b/advisories/unreviewed/2024/01/GHSA-mvp3-ghv2-w5rp/GHSA-mvp3-ghv2-w5rp.json new file mode 100644 index 00000000000..d9d066ff2c8 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-mvp3-ghv2-w5rp/GHSA-mvp3-ghv2-w5rp.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mvp3-ghv2-w5rp", + "modified": "2024-01-08T09:30:35Z", + "published": "2024-01-08T09:30:35Z", + "aliases": [ + "CVE-2024-0305" + ], + "details": "A vulnerability was found in Guangzhou Yingke Electronic Technology Ncast up to 2017 and classified as problematic. Affected by this issue is some unknown functionality of the file /manage/IPSetup.php of the component Guest Login. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249872.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0305" + }, + { + "type": "WEB", + "url": "https://github.com/2267787739/cve/blob/main/logic.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249872" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249872" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-200" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T09:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json b/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json new file mode 100644 index 00000000000..e98910a2f53 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-pgpx-675x-4jcv/GHSA-pgpx-675x-4jcv.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pgpx-675x-4jcv", + "modified": "2024-01-08T09:30:34Z", + "published": "2024-01-08T09:30:34Z", + "aliases": [ + "CVE-2023-29049" + ], + "details": "The \"upsell\" widget at the portal page could be abused to inject arbitrary script code. Attackers that manage to lure users to a compromised account, or gain temporary access to a legitimate account, could inject script code to gain persistent code execution capabilities under a trusted domain. User input for this widget is now sanitized to avoid malicious content the be processed. No publicly available exploits are known.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29049" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0005.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6248_7.10.6_2023-09-19.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T09:15:20Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-v525-j46w-8q9c/GHSA-v525-j46w-8q9c.json b/advisories/unreviewed/2024/01/GHSA-v525-j46w-8q9c/GHSA-v525-j46w-8q9c.json new file mode 100644 index 00000000000..bfbaaa4cfd7 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-v525-j46w-8q9c/GHSA-v525-j46w-8q9c.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v525-j46w-8q9c", + "modified": "2024-01-08T09:30:34Z", + "published": "2024-01-08T09:30:34Z", + "aliases": [ + "CVE-2024-0301" + ], + "details": "A vulnerability classified as critical was found in fhs-opensource iparking 1.5.22.RELEASE. This vulnerability affects the function getData of the file src/main/java/com/xhb/pay/action/PayTempOrderAction.java. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249868.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0301" + }, + { + "type": "WEB", + "url": "https://github.com/laoquanshi/heishou/blob/main/iparking-SQL.pdf" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249868" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249868" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T07:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-w69p-f797-2jf5/GHSA-w69p-f797-2jf5.json b/advisories/unreviewed/2024/01/GHSA-w69p-f797-2jf5/GHSA-w69p-f797-2jf5.json new file mode 100644 index 00000000000..eb46c1d76be --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-w69p-f797-2jf5/GHSA-w69p-f797-2jf5.json @@ -0,0 +1,46 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w69p-f797-2jf5", + "modified": "2024-01-08T09:30:34Z", + "published": "2024-01-08T09:30:34Z", + "aliases": [ + "CVE-2024-0304" + ], + "details": "A vulnerability has been found in Youke365 up to 1.5.3 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/collect.php. The manipulation of the argument url leads to server-side request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249871.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-0304" + }, + { + "type": "WEB", + "url": "https://note.zhaoj.in/share/3jF3Xpl3ttlZ" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.249871" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.249871" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T08:15:36Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json b/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json new file mode 100644 index 00000000000..ac886d63e21 --- /dev/null +++ b/advisories/unreviewed/2024/01/GHSA-xr84-qwr9-vj33/GHSA-xr84-qwr9-vj33.json @@ -0,0 +1,42 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-xr84-qwr9-vj33", + "modified": "2024-01-08T09:30:35Z", + "published": "2024-01-08T09:30:35Z", + "aliases": [ + "CVE-2023-29052" + ], + "details": "Users were able to define disclaimer texts for an upsell shop dialog that would contain script code that was not sanitized correctly. Attackers could lure victims to user accounts with malicious script code and make them execute it in the context of a trusted domain. We added sanitization for this content. No publicly available exploits are known.\n\n", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" + } + ], + "affected": [ + + ], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29052" + }, + { + "type": "WEB", + "url": "https://documentation.open-xchange.com/security/advisories/csaf/oxas-adv-2023-0006.json" + }, + { + "type": "WEB", + "url": "https://software.open-xchange.com/products/appsuite/doc/Release_Notes_for_Patch_Release_6251_7.10.6_2023-09-25.pdf" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-79" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2024-01-08T09:15:20Z" + } +} \ No newline at end of file